The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content. This vulnerability class is related to improper access control, which can lead to unauthorized information disclosure. A [truncated]
The Duplicate Post WordPress plugin before 1.5.5 is vulnerable to arbitrary post deletion due to a lack of per-object authorization checks in bulk copy and delete operations. This vulnerability allows any user with granted access to the plugin to permanently delete posts, including those belonging to other users. The CVE record was published on 2026-08-10T07:16:51.377Z and has not been modified since then [truncated]